Privacy Policy — Group Audit for Jira

Effective date: 7 August 2026

Summary: Group Audit runs entirely inside your Atlassian instance on Atlassian Forge infrastructure. It is read-only, stores no data, uses no external servers, no analytics and no cookies. No data — personal or otherwise — is ever transmitted to us or to any third party.

1. Who we are

Group Audit for Jira ("the app") is operated by Fabian Hönes (contact: kontakt@arbeitstyp.de). For the data the app reads inside your Jira instance we are neither a data controller nor a data processor — that data is processed entirely within your Atlassian environment and never reaches us (sections 2–4). We act as a data controller only for support correspondence you choose to send us directly (section 5).

2. What the app does with data

When a Jira administrator runs a scan, the app reads Jira configuration data through the official Jira Cloud REST API: permission schemes, notification schemes, project roles, issue security schemes, filter and dashboard sharing settings, application role groups, and the member list of the selected group (display names and active/inactive status).

This data is processed only inside your Atlassian instance and only for the moment of the scan, to display the audit report in the administrator's browser. The app has no database and no storage: results exist only in the administrator's browser session and, if the administrator chooses to export them, in a CSV file saved locally on their own device. When the page is closed, the results are gone.

3. What the app does not do

The app has no backend servers of its own, makes no network requests to any system other than your own Atlassian instance (no egress), does not modify any Jira data (read-only permission scopes only), and does not use cookies, analytics, tracking or advertising of any kind. We — the app vendor — never see, receive or store any of your data. We cannot access your Jira instance.

4. Hosting and platform

The app runs on Atlassian Forge, Atlassian's own app platform. Atlassian's processing of your data is governed by the Atlassian Privacy Policy and your agreements with Atlassian. Purchases and billing for the app are handled entirely by Atlassian through the Atlassian Marketplace; we receive aggregated sales reporting from Atlassian, not your payment data.

5. Support requests

If you contact us at kontakt@arbeitstyp.de, we use your email address and the content of your message solely to answer your request (legal basis: Art. 6(1)(f) GDPR — responding to your inquiry). Support emails are deleted once the request is resolved, unless a longer retention is legally required.

6. Your rights

Under the GDPR you have the rights of access, rectification, erasure, restriction, data portability and objection regarding personal data we process (which, per the above, is limited to support correspondence). You also have the right to lodge a complaint with a supervisory authority. For any request, contact kontakt@arbeitstyp.de.

7. Changes

If the app ever changes in a way that affects data handling, this policy will be updated before the change ships, with a new effective date.